SAP security note 2735924, "[CVE-2019-0352] Improper session management in SAP Business Objects Business Intelligence Platform (CMC)", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
UPDATE 12th May 2020: This security note has been updated. For more detailed information, see Security Note 2878555 – Update 1 to Security Note 2735924 – [CVE-2019-0352] Improper session management in SAP Business Objects Business Intelligence Platform (CMC).
In SAP Business Objects Business Intelligence Platform, there are spots where dynamic pages (like JSP) are cached. Due to this, even after logout, an attacker can see sensitive information via the cache and can open the dynamic pages.
Solution
Cache has been disabled in dynamic pages wherever it’s not managed well.
This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released. For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559 in the References section.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2735924
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
